← NZ Leads home
Terms Privacy Billing Acceptable Use Cookies DPA

NZ Leads Data Processing Addendum

Effective and last updated: July 21, 2026
Document version: 2026-07-21

This Data Processing Addendum (“DPA”) forms part of the NZ Leads Terms of Use, an Order, or another written agreement governing Customer’s use of the Services (collectively, the “Agreement”) between NZ Leads Inc. (“NZ Leads”) and the business or other legal entity that obtains the Services (“Customer”).

This DPA applies to the extent NZ Leads Processes Customer Personal Data on Customer’s behalf. It is intended to satisfy applicable requirements for contracts between controllers and processors, businesses and service providers or contractors, and comparable parties under Data Protection Laws.

NZ Leads Inc.
857 N Orange Dr
Los Angeles, CA 90038
United States
Email: support@nzleads.com
Telephone: +1 (818) 446-6122

1. Definitions

In this DPA:

“Applicable Data Protection Law” or “Data Protection Laws” means privacy, data protection, breach-notification, and similar laws that apply to the Processing of Customer Personal Data under the Agreement, including, where applicable, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”), the EU General Data Protection Regulation 2016/679 (“EU GDPR”), and the United Kingdom GDPR and Data Protection Act 2018 (“UK Data Protection Laws”).

“Customer Personal Data” means Personal Data contained in Customer Data that NZ Leads Processes on Customer’s behalf to provide the Services. It excludes information for which NZ Leads acts as an independent controller or business, as described in the Privacy Policy.

“Data Subject Request” means a request by an individual to exercise a right under Applicable Data Protection Law.

“EEA” means the European Economic Area.

“EU SCCs” means the standard contractual clauses adopted by European Commission Implementing Decision (EU) 2021/914 of June 4, 2021.

“Personal Data” has the meaning given by Applicable Data Protection Law and includes “personal information” where that term applies.

“Process,” “Processing,” “Controller,” “Processor,” “Business,” “Service Provider,” “Contractor,” “Sell,” and “Share” have the meanings given by Applicable Data Protection Law.

“Security Incident” means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data in NZ Leads’ possession or control. Security Incident does not include unsuccessful attempts or activities that do not compromise Customer Personal Data, such as blocked scans, pings, denial-of-service attempts, or failed login attempts.

“Subprocessor” means a third party engaged by NZ Leads to Process Customer Personal Data on Customer’s behalf.

Capitalized terms not defined here have the meanings in the Agreement.

2. Scope and roles

2.1 Customer instructions

Customer instructs NZ Leads to Process Customer Personal Data:

  1. to provide, secure, support, and improve the contracted Services;
  2. according to Customer’s use, configuration, integrations, and documented instructions;
  3. as described in the Agreement, this DPA, and Annex A;
  4. to prevent or address fraud, abuse, security threats, or technical problems; and
  5. as required by applicable law.

The Agreement and Customer’s authorized use of the Services constitute Customer’s documented instructions. Additional instructions must be consistent with the Agreement and Applicable Data Protection Law. If an additional instruction requires material work outside the Services, the parties will agree on scope, fees, and implementation.

NZ Leads will inform Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law, unless law prohibits that notice. NZ Leads may suspend the affected Processing while the parties address the instruction.

2.2 Roles

For Customer Personal Data, Customer is the Controller, Business, or equivalent responsible party, and NZ Leads is the Processor, Service Provider, Contractor, or equivalent recipient, except where Applicable Data Protection Law assigns a different role.

Each party is independently responsible for compliance with the laws that apply to it. This DPA does not make the parties joint controllers or create a partnership.

2.3 NZ Leads’ independent processing

NZ Leads may act as an independent Controller or Business for account administration, direct billing, security, fraud and abuse prevention, legal compliance, business communications, and establishing, exercising, or defending legal claims. Such Processing is governed by the Privacy Policy rather than this DPA, except to the extent Applicable Data Protection Law provides otherwise.

3. Customer obligations

Customer represents, warrants, and agrees that:

  1. Customer has a valid legal basis and all rights, notices, consents, and permissions required for NZ Leads and its Subprocessors to Process Customer Personal Data under the Agreement;
  2. Customer’s instructions comply with Applicable Data Protection Law;
  3. Customer will not instruct NZ Leads to Process data that the Agreement or Services are not designed to Process;
  4. Customer will configure access, retention, integrations, recording, transcription, messaging, and AI features lawfully and appropriately;
  5. Customer will respond to Data Subject Requests and regulator inquiries for which Customer is responsible; and
  6. Customer will not rely on the Services as its sole legally required archive.

Customer is responsible for the accuracy, quality, and legality of Customer Personal Data and the means by which Customer acquired it. Customer must provide any legally required privacy, calling, artificial-intelligence, recording, and transcription disclosures and obtain any legally required consent from affected individuals. Customer’s acceptance of the Agreement is not consent from a call participant or message recipient.

4. Processing restrictions

NZ Leads will:

  1. Process Customer Personal Data only on Customer’s documented instructions, including as necessary to provide the Services, unless required by applicable law;
  2. ensure persons authorized to Process Customer Personal Data are subject to confidentiality obligations;
  3. implement the security measures described in Annex B;
  4. assist Customer as described in this DPA; and
  5. not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer or for a purpose other than the business purposes specified in the Agreement, except as permitted by Applicable Data Protection Law.

NZ Leads will not Sell or Share Customer Personal Data for cross-context behavioral advertising. NZ Leads will not use Customer Personal Data to train an NZ Leads generalized AI model for unrelated customers unless Customer expressly opts in in writing. Processing by an AI or other Subprocessor remains subject to this DPA, the applicable subprocessing agreement, and Customer’s instructions or configuration.

NZ Leads may use information that has been aggregated or de-identified in accordance with Applicable Data Protection Law, provided that NZ Leads maintains it in de-identified form and does not attempt to re-identify it except to test whether de-identification processes comply with law.

5. CCPA service-provider and contractor terms

To the extent the CCPA applies to Customer Personal Data:

  1. Customer discloses Customer Personal Data to NZ Leads only for the limited and specified business purposes described in the Agreement, this DPA, and Annex A.
  2. NZ Leads will comply with applicable obligations under the CCPA and provide the same level of privacy protection for Customer Personal Data as the CCPA requires of businesses.
  3. NZ Leads will not Sell or Share Customer Personal Data.
  4. NZ Leads will not retain, use, or disclose Customer Personal Data for a commercial purpose other than the business purposes specified in the Agreement, or outside the direct business relationship between Customer and NZ Leads, except as the CCPA permits.
  5. NZ Leads will not combine Customer Personal Data received from or on behalf of Customer with Personal Data received from another person or collected from NZ Leads’ own interaction with an individual, except as the CCPA permits.
  6. Customer may take reasonable and appropriate steps to help ensure NZ Leads uses Customer Personal Data consistently with Customer’s CCPA obligations.
  7. NZ Leads will notify Customer if NZ Leads determines it can no longer meet its applicable CCPA obligations.
  8. Customer may, upon notice, take reasonable and appropriate steps to stop and remediate NZ Leads’ unauthorized use of Customer Personal Data.
  9. NZ Leads will require each Subprocessor that Processes Customer Personal Data to be bound by written terms that provide the level of protection required by the CCPA.

The parties acknowledge that Customer’s disclosure of Customer Personal Data to NZ Leads is not a Sale or Share when made under and in compliance with this DPA.

6. Confidentiality

NZ Leads will limit access to Customer Personal Data to personnel and Subprocessors who need access to perform obligations under the Agreement. NZ Leads will ensure that personnel authorized to Process Customer Personal Data are bound by confidentiality duties and receive privacy and security guidance appropriate to their roles.

Confidentiality obligations survive the end of the applicable person’s engagement and the termination of the Agreement.

7. Security

NZ Leads will maintain reasonable and appropriate technical and organizational measures designed to protect Customer Personal Data against a Security Incident, taking into account the nature, scope, context, and purpose of Processing and the risks to individuals. Current measures are summarized in Annex B.

Customer acknowledges that no system is completely secure. Customer is responsible for:

  • securing its accounts, credentials, devices, networks, endpoints, and integrations;
  • managing user and administrator permissions;
  • using available security settings;
  • promptly removing access for former personnel; and
  • notifying NZ Leads promptly of suspected unauthorized use.

NZ Leads may update its security measures as technology and risks evolve, provided an update does not materially reduce the overall protection of Customer Personal Data during an active Order.

Nothing in this DPA represents that NZ Leads holds a particular certification or has completed a particular independent audit unless NZ Leads confirms that status separately in writing.

8. Security Incidents

NZ Leads will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data. Notice may be delivered to Customer’s account administrator, security contact, or other account email.

To the extent reasonably available, the notice will describe:

  1. the nature of the Security Incident;
  2. categories of affected data and individuals;
  3. likely consequences;
  4. measures taken or proposed to address the incident; and
  5. a contact for follow-up.

Information may be provided in phases as an investigation progresses. NZ Leads’ notice or response is not an admission of fault or liability.

NZ Leads will take reasonable steps to contain, investigate, and mitigate a Security Incident and will reasonably cooperate with Customer’s legally required response. Customer is responsible for notifying individuals, regulators, or others unless applicable law expressly requires NZ Leads to do so.

9. Subprocessors

9.1 General authorization

Customer gives NZ Leads general written authorization to engage Subprocessors. Subprocessors may include infrastructure, hosting, database, authentication, security, analytics, support, payment, telephony, messaging, recording, transcription, AI, email, storage, publishing, and Customer-selected integration providers.

NZ Leads will maintain a current Subprocessor list or make it available on reasonable request. Customer may request notice of a new Subprocessor by emailing support@nzleads.com.

9.2 Requirements

Before a Subprocessor Processes Customer Personal Data, NZ Leads will enter into a written agreement requiring protections appropriate to the Processing and substantially consistent with NZ Leads’ applicable obligations under this DPA.

NZ Leads remains responsible for the Subprocessor’s performance of the data-protection obligations delegated to it, subject to the liability limitations in the Agreement and this DPA.

9.3 Objections

Customer may object to a new Subprocessor on reasonable data-protection grounds by giving written notice within 15 days after receiving notice of the change. The parties will work in good faith to identify a commercially reasonable alternative. If no alternative is reasonably available, NZ Leads may allow Customer to stop using the affected feature or terminate the affected Order. An objection does not create a right to a refund for Services already provided or costs already incurred, except where required by law or agreed in the affected Order.

10. Data Subject Requests

Taking into account the nature of the Processing, NZ Leads will provide reasonable assistance through available product functionality or other appropriate measures so Customer can respond to Data Subject Requests.

If NZ Leads receives a request relating to Customer Personal Data for which Customer is responsible, NZ Leads may:

  1. direct the requester to Customer;
  2. notify Customer, unless law prohibits notice; and
  3. not respond substantively except on Customer’s documented instructions or as required by law.

Customer is responsible for verifying the requester’s identity, determining whether a right applies, and providing the response. NZ Leads may charge reasonable fees for exceptional assistance that requires material work outside standard product functionality, to the extent law permits.

11. Assistance and compliance information

Taking into account the nature of Processing and information available to NZ Leads, NZ Leads will provide reasonable assistance with:

  • security and breach-notification obligations;
  • data-protection impact assessments;
  • prior consultation with regulators; and
  • information reasonably necessary to demonstrate compliance with applicable processor obligations.

NZ Leads may provide relevant policies, summaries, questionnaires, reports, or other compliance information under appropriate confidentiality restrictions. Assistance beyond standard documentation and product functionality may be subject to reasonable fees when law permits.

12. Audits

No more than once in any 12-month period, Customer may request information reasonably necessary to demonstrate NZ Leads’ compliance with this DPA. The frequency limit does not apply following a Security Incident affecting Customer Personal Data or when a competent regulator requires a further audit.

The parties will first use current third-party reports, certifications, summaries, questionnaires, and other documentation, if available and sufficient. If those materials are insufficient, Customer may request a remote audit or, where legally required and reasonably necessary, an on-site audit.

An audit must:

  1. be conducted by Customer or an independent auditor that is not NZ Leads’ competitor;
  2. be subject to confidentiality obligations;
  3. occur during normal business hours with reasonable advance written notice;
  4. avoid access to another customer’s data or confidential information;
  5. avoid unreasonably disrupting operations; and
  6. be limited to systems and Processing relevant to Customer Personal Data.

Customer bears its audit costs and reimburses NZ Leads’ reasonable costs for assistance beyond ordinary compliance support, unless an audit identifies a material breach by NZ Leads or Applicable Data Protection Law prohibits cost allocation.

13. Return, deletion, and retention

During the term, Customer may use available functionality to access or export certain Customer Data. Customer should export needed data before access ends.

Upon termination or Customer’s documented request, and subject to the Agreement, NZ Leads will delete or return Customer Personal Data when reasonably practicable unless law requires or permits retention. NZ Leads may retain limited information:

  • in restricted backups or archival disaster-recovery copies under applicable retention schedules when immediate deletion is not reasonably practicable;
  • for security, fraud prevention, tax, accounting, and audit obligations;
  • to document transactions, consent, suppression, policy acceptance, and service delivery;
  • under a targeted legal hold or to establish, exercise, or defend legal claims, including a payment dispute; and
  • in aggregated or de-identified form.

Retained Customer Personal Data remains protected by this DPA and will not be used for another purpose. When the reason for active retention ends, NZ Leads will delete or de-identify the data in active systems. Customer Personal Data remaining only in a restricted backup or archive will be isolated from ordinary use and, if restored to an active system, deleted before ordinary Processing resumes unless another lawful retention basis applies.

Cancellation does not necessarily cause immediate deletion. The Privacy Policy provides additional retention criteria.

14. Government and legal requests

If NZ Leads is legally compelled to disclose Customer Personal Data, NZ Leads will notify Customer before disclosure unless law prohibits notice. Where appropriate and lawful, NZ Leads will direct the requesting authority to Customer, challenge an unlawful or overbroad request, and disclose only information reasonably necessary to comply.

Nothing in this DPA requires a party to violate applicable law.

15. International transfers

15.1 General

Customer authorizes NZ Leads and its Subprocessors to Process Customer Personal Data in the United States and other countries where they operate, subject to the transfer safeguards required by Applicable Data Protection Law.

15.2 EEA transfers

If Customer Personal Data protected by the EU GDPR is transferred to NZ Leads in a country that is not recognized as providing an adequate level of protection and no other lawful transfer mechanism applies, the EU SCCs are incorporated by reference as follows:

  1. Module Two applies when Customer is a controller and NZ Leads is a processor.
  2. Module Three applies when Customer is a processor and NZ Leads is a subprocessor.
  3. The optional docking clause in Clause 7 applies.
  4. In Clause 9, Option 2 applies, with the notice period stated in Section 9.3 of this DPA.
  5. In Clause 11, the optional independent dispute-resolution language does not apply.
  6. In Clause 17, Option 1 applies and the laws of Ireland govern.
  7. Under Clause 18, the courts of Ireland have jurisdiction.
  8. Annexes A and B of this DPA complete Annexes I and II of the EU SCCs.
  9. The competent supervisory authority or authorities will be determined in accordance with Clause 13 of the EU SCCs and identified in Annex I.C based on the circumstances of the relevant transfer.

For Module Three, Customer represents that the relevant controller has authorized Customer to appoint NZ Leads as a subprocessor and to enter into the EU SCCs on its behalf where required.

15.3 United Kingdom transfers

For a restricted transfer subject to UK Data Protection Laws, the then-current International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner’s Office (“UK Addendum”) is incorporated and completed using the information in this DPA. The parties are the exporter and importer identified in Annex A; the selected SCC modules and clauses are those stated above; Annexes A and B provide the required processing and security information; and either party may end the UK Addendum as permitted by its mandatory terms.

15.4 Switzerland

For a transfer subject to the Swiss Federal Act on Data Protection, the EU SCCs apply with adaptations required by Swiss law. References to the EU GDPR include the Swiss Federal Act on Data Protection where applicable; references to a supervisory authority include the Swiss Federal Data Protection and Information Commissioner; and individuals in Switzerland may enforce applicable rights in Switzerland.

15.5 Priority

If a mandatory term of the EU SCCs or UK Addendum conflicts with this DPA or the Agreement, the mandatory transfer term controls for the affected transfer.

16. Liability

Each party’s liability arising out of or relating to this DPA is subject to the exclusions and limitations of liability in the Agreement, except to the extent a limitation is prohibited by Applicable Data Protection Law or the EU SCCs or UK Addendum.

No person is entitled to recover compensation more than once for the same loss.

17. Term and conflict

This DPA begins when the Agreement takes effect and continues while NZ Leads Processes Customer Personal Data.

If this DPA conflicts with the Agreement regarding Processing of Customer Personal Data, this DPA controls. If Annex A or Annex B conflicts with the body of this DPA, the body controls. Mandatory transfer terms control as stated in Section 15.5.

Except as modified by this DPA, the Agreement remains in effect.

18. Updates

NZ Leads may update this DPA when reasonably necessary to reflect changes in law, regulatory guidance, Subprocessors, or the Services. An update will not materially reduce the protection of Customer Personal Data during an active Order unless required by law or Customer agrees. The current version will be posted with its effective date.

19. Contact

Questions, requests, and notices concerning this DPA should be sent to:

NZ Leads Inc.
Attention: Privacy
857 N Orange Dr
Los Angeles, CA 90038
United States
Email: support@nzleads.com
Telephone: +1 (818) 446-6122

Annex A — Details of Processing

A. Parties

Data exporter

The data exporter is Customer and, where Customer acts as a processor, the relevant Customer affiliate or controller identified in the Agreement or Order.

Customer’s contact details are those associated with its account or stated in the applicable Order.

Customer’s role is Controller or Processor, as applicable.

Data importer

NZ Leads Inc.
857 N Orange Dr
Los Angeles, CA 90038
United States
support@nzleads.com
+1 (818) 446-6122

NZ Leads’ role is Processor or Subprocessor, as applicable.

B. Subject matter and duration

The subject matter is NZ Leads’ Processing of Customer Personal Data to provide the Services described in the Agreement and Customer’s configuration.

Processing continues for the term of the Agreement and for the limited post-termination period described in Section 13.

C. Nature and purpose

Processing may include:

  • collecting and receiving lead, contact, account, and integration data;
  • hosting, organizing, retrieving, displaying, and transmitting data;
  • receiving and sending messages;
  • placing, receiving, routing, recording, and transcribing calls;
  • generating summaries, drafts, classifications, extracted fields, and other AI-assisted outputs;
  • scheduling, lead routing, and workflow automation;
  • creating, reviewing, submitting, and reporting on press releases;
  • integrating with Customer-selected lead sources, CRMs, calendars, communication channels, and destinations;
  • securing, monitoring, troubleshooting, supporting, and maintaining the Services; and
  • deleting, returning, aggregating, or de-identifying data as described in the Agreement.

D. Categories of individuals

Customer Personal Data may relate to:

  • Customer’s administrators, users, personnel, contractors, and representatives;
  • prospective and current customers, leads, contacts, and referral sources;
  • callers, call recipients, message senders, and message recipients;
  • people whose details are included in connected accounts, calendars, contact lists, knowledge bases, recordings, transcripts, messages, attachments, or press-release content; and
  • other individuals whose Personal Data Customer directs the Services to Process.

E. Categories of Personal Data

Depending on Customer’s use, Customer Personal Data may include:

  • names, business contact details, account identifiers, and profile data;
  • lead-source, location, campaign, referral, and attribution information;
  • message content, email, SMS, attachments, notes, and conversation history;
  • phone numbers, caller and recipient identifiers, call audio, voicemail, recordings, transcripts, summaries, outcomes, timestamps, duration, and transfer information;
  • calendar, appointment, availability, and scheduling information;
  • prompts, scripts, knowledge-base content, dynamic variables, offers, and instructions;
  • press-release drafts, quotations, names, titles, biographies, images, media contacts, and publication information;
  • integration tokens, identifiers, settings, event data, and destination fields;
  • device, network, authentication, access, activity, and security logs; and
  • any other Personal Data Customer submits or directs the Services to Process.

F. Sensitive data

The Services are not designed for unnecessary sensitive data. Customer Data may nevertheless contain sensitive or special-category information if Customer or an individual includes it in free text, a message, a call, a recording, a transcript, an attachment, a knowledge base, or an integration.

Customer must not submit sensitive or special-category data unless it is necessary for a lawful use of the Services and Customer has satisfied all additional legal requirements. Customer must not use the Services for payment-card security codes, full payment-card data outside approved payment fields, government authentication secrets, or health information subject to a regulated processing arrangement unless NZ Leads has expressly agreed in writing.

No special restriction or safeguard beyond the Agreement applies unless the parties agree in writing or Applicable Data Protection Law requires it.

G. Frequency

Processing may be continuous or occur whenever Customer or an authorized integration uses the Services.

H. Retention

Retention follows Section 13 of this DPA, the Privacy Policy, Customer’s available settings and instructions, the applicable Order, backup and archival retention schedules, and applicable legal obligations.

I. Subprocessor subject matter

Subprocessors may provide infrastructure, hosting, database, storage, authentication, security, analytics, support, payment, telephony, messaging, recording, transcription, AI, email, content processing, publishing, and Customer-selected integration functions for the duration necessary to provide those functions.

Annex B — Technical and Organizational Measures

NZ Leads maintains measures reasonably designed for the nature and risk of the Services. Measures may include, as applicable:

1. Governance and personnel

  • documented security and privacy responsibilities;
  • confidentiality obligations;
  • role-appropriate security and privacy guidance;
  • access approval and removal processes; and
  • incident-response responsibilities.

2. Access control

  • unique user or workforce identities where appropriate;
  • authentication controls;
  • role-based or least-privilege access principles;
  • credential and secret-management practices; and
  • review or revocation of access when no longer needed.

3. Data and transmission protection

  • encryption in transit using current industry-standard protocols where supported;
  • encryption at rest for applicable production storage where supported;
  • logical separation of customer data;
  • controlled handling of secrets, tokens, and credentials; and
  • minimization of production data used in development or testing.

4. Infrastructure and operations

  • change-management and deployment practices;
  • logging and monitoring appropriate to system risk;
  • vulnerability and patch-management processes;
  • malware and endpoint protections where appropriate; and
  • capacity, availability, backup, and recovery practices appropriate to the Services.

5. Secure development

  • code review and testing practices;
  • dependency and vulnerability management;
  • separation of development and production environments where appropriate; and
  • remediation based on severity and risk.

6. Incident management

  • processes to identify, escalate, investigate, contain, and remediate suspected incidents;
  • preservation of relevant investigation records;
  • internal and external communication procedures; and
  • post-incident review where appropriate.

7. Subprocessor management

  • risk-based review of relevant providers;
  • written data-protection and confidentiality terms;
  • access limited to the services provided; and
  • review of material provider changes where appropriate.

8. Business continuity

  • backups and restoration procedures appropriate to the Services;
  • operational recovery planning; and
  • periodic review or testing of selected recovery processes.

Security measures are not a guarantee that every incident will be prevented. NZ Leads may replace a measure with an alternative that provides substantially equivalent or greater overall protection.